Gentoo Archives: gentoo-hardened

From: "Anthony G. Basile" <basile@××××××××××××××.edu>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] hardened profile for desktops?
Date: Fri, 08 Jun 2012 18:03:39
Message-Id: 4FD21BC0.2030002@opensource.dyc.edu
In Reply to: Re: [gentoo-hardened] hardened profile for desktops? by Alex Efros
1 On 06/08/2012 09:06 AM, Alex Efros wrote:
2 > Hi!
3 >
4 > On Fri, Jun 08, 2012 at 07:15:40AM -0400, Aaron W. Swenson wrote:
5 >>>> I started a discussion on gentoo-user about the fact that the
6 >>>> hardened profile appears to only be for servers and not desktops.
7 >>>> I thought I'd check with you guys on this. Is that the case?
8 >
9 > Actually, I see no reasons to NOT use hardened on desktops.
10
11 True
12
13 >
14 > Only critical bug is broken VMware/VirtualBox on amd64+hardened.
15
16 This one is a moving target. Sometimes broken, times fixed. kvm is
17 working very well of late.
18
19 >
20 > Everything else is works fine on hardened AFAIK. Even unsupported
21 > nvidia-drivers works fine (they needed for 3D acceleration in VMware).
22 > Sometimes you need to get extra patches from bugzilla or run paxctl,
23 > but this isn't too much headache to avoid it at cost of significantly
24 > lower overall security.
25 >
26
27 nouveau works great on hardened desktops
28
29 radeon compiled with llvm needs some fancy pax markings, but also works
30
31 --
32 Anthony G. Basile, Ph. D.
33 Chair of Information Technology
34 D'Youville College
35 Buffalo, NY 14201
36 (716) 829-8197

Replies

Subject Author
Re: [gentoo-hardened] hardened profile for desktops? "Javier Juan Martínez Cabezón" <tazok.id0@×××××.com>
Re: [gentoo-hardened] hardened profile for desktops? Alex Efros <powerman@××××××××.name>